{"schema_version":"1.9.0","id":"openSUSE-SU-2026:21574-1","published":"2026-08-12T16:07:50Z","modified":"2026-08-14T18:23:46.282462804Z","related":["CVE-2026-10722"],"upstream":["CVE-2026-10722"],"summary":"Security update for amazon-ecs-init","details":"This update for amazon-ecs-init fixes the following issue:\n\nUpdate to version 1.106.0.\n\nSecurity issues fixed:\n\n- CVE-2026-10722: github.com/cilium/ebpf: interger overflow when performing BTF string offset boundary check can lead\n  to crash when malformed ELF/BTF input is parsed (bsc#1267794).\n\nOther updates and bugfixes:\n\n- Version 1.106.0:\n  * Feature - Feature - Add FIS-driven DNS refresh add-sources endpoint\n    for network-latency and network-packet-loss faults (#5029)\n  * Enhancement - Enhancement: Update SSM Agent version to 3.3.4624.0\n    for ECS exec (#5054)\n  * Enhancement - Backfill host DNS config on isolated platform (#5047)\n  * Enhancement - Bump github.com/aws/smithy-go from 1.27.3 to 1.27.4\n    in /agent (#5051)\n  * Enhancement - Bump github.com/aws/aws-sdk-go-v2/credentials in /ecs-agent,\n    /agent and /ecs-init to 1.19.29 (#5050)\n  * Enhancement - Bump actions/setup-go from 6 to 7 in /.github/workflows (#5049)\n  * Enhancement - Update Go version to 1.25.12 (#5048)\n  * Enhancement - Bump github.com/vishvananda/netlink from 1.2.1-beta.2 to 1.3.1\n    in /ecs-agent, /agent and /ecs-init (#5037)\n  * Enhancement - Bump github.com/aws/aws-sdk-go-v2/credentials from 1.19.22 to\n    1.19.28 in /agent (#5038)\n  * Enhancement - Bump github.com/hectane/go-acl from 0.0.0-20190604041725-da78bae5fc95\n    to 1.0.0 in /agent (#5022)\n  * Enhancement - chore(deps): bump github.com/cilium/ebpf from v0.16.0 to v0.22.0\n    in /agent (#5034)\n  * Enhancement - Bump golang.org/x/net from 0.48.0 to 0.55.0 in\n    /ecs-agent/daemonimages/csidriver (#5031)\n  * Enhancement - api-2.json: Add CONFIDENTIAL_PARTITION and attestationPolicy to\n    api model (#5033)\n  * Bugfix - Fix flaky TestHostResourceManagerTrickleQueue integration test (#5026)\n","affected":[{"package":{"name":"amazon-ecs-init","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/amazon-ecs-init&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.106.0-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"amazon-ecs-init":"1.106.0-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21574-1.json"}}],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267794"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-10722"}]}